Skip to main content

Mobile apps have transformed the way we interact with services, manage our personal information, and interact with organisations. But this increased reliance on technology brings a breadth of cybersecurity implications, from hacking to fraud and even stalking.

That’s why Secured by Design, the official police security initiative, has expanded its Secure Connected Device (SCD) scheme to accommodate mobile applications. This new accreditation enables organisations to demonstrate best-practice security for their app, helping users feel confident that appropriate steps have been taken to protect their data.

In this FAQ, we speak to National SBD Manager and Lead for the SCD Scheme, Michelle Kradolfer, to answer some of the most common questions about the app accreditation – including why it was introduced, what it tests and how the assessment process works.

Tell us about the new app accreditation

Of course – the SCD app accreditation was introduced so users can confidently use mobile applications, knowing that all reasonable steps have been taken to protect their personal data and that recognised industry standards have been met.


“SCD accreditation dramatically reduces your attack surface, prevents data breaches and earns the police-endorsed mark that drives consumer confidence.”


While higher-assurance options exist, cost remains a barrier for many companies. To bridge this gap, Secured by Design collaborated with Secarma, a leading UK cyber security firm, to develop a cost-effective certification level that assesses apps against OWASP ASVS/MASVS.

Why was the app accreditation introduced?

A very high percentage of mobile apps fail to meet even baseline security standards. For example, a 2023 NowSecure benchmark analysis found that 95% of nearly 6,500 leading mobile apps failed at least one of the seven OWASP MASVS security categories. This has alarming implications by compromising users’ personal and financial data which ultimately leaves them vulnerable to cyberattacks.

Gaining SCD accreditation informs consumers that the app is built to withstand common attacks, instilling confidence and fostering a safer digital environment for all.

Can you explain the accreditation process?

The process is clear, cost-effective and developer-friendly – we’ve summarised it in 10 simple steps:

What exactly is tested?

Good question – your app will be tested against OWASP ASVS/MASVS, verifying that it meets basic security controls for a robust and resilient deployment. This includes checks across six key testing areas:

Authentication mechanisms and session management

Ensures users are securely verified and that their logged-in sessions are protected from hijacking, misuse or unauthorised access.

Secure default configurations and deployment standards

Confirms applications are safely configured and deployed, so they are not exposed to avoidable risks from misconfigurations

Use of cryptography to protect sensitive data

Checks that sensitive information is properly encrypted using strong, modern algorithms and securely managed keys, protecting it from exposure and misuse.

Safe error handling and logging

Ensures apps do not leak sensitive information through errors while maintaining secure, useful logs for detecting and investigating security incidents.

Input validation and output encoding

Checks that all user-supplied data is handled safely throughout an application.

Defenses against common threats, such as SQL injection, cross-site scripting (XSS), and insecure direct object references

Confirms the app consistently validates input, encodes output, and enforces server-side authorisation to prevent attackers from accessing unauthorised data.

How long does it take to get accredited?

The timeline for accreditation depends on a few things – mainly how quickly you can complete certification with the recommended testing house and when our team can review your documents.

With no delays, you could be accredited in just two weeks.

How often must accredited apps be re-assessed?

To maintain SCD accreditation, retesting is required every 12 months as this ensures the app maintains an adequate level of security.

Why is it important to consider user data?

Mobile apps have become a prime target for cyberattacks, largely due to inadequate security measures that leaves user exposed to substantial risks.

Moreover, malicious software like viruses, trojans and spyware are frequently used to gain unauthorized access to sensitive information and personal data – which is why it’s more important than ever to implement strong cybersecurity across your platforms.

“This threat is almost certain to continue increasing as technology evolves.”

In particular, apps are alarmingly exploited in Violence Against Women & Girls (VAWG), which actively enables stalking and harassment.

An example of this is the breach of the “Tea Dating Advice” app in the US. This women-only safety app, with 1.6 million users, suffered a breach which exposed 72,000 user images, leading to doxxing and online harassment.

Therefore, the SCD app certification aims to combat these weaknesses, enabling users (especially women and girls) to use apps with greater confidence and security.

How does SCD accreditation differ from other cybersecurity certifications?

Unlike other cybersecurity certifications – such as Cyber Essentials and ISO 27001 – SCD accreditation is unique due to the fact it’s police-endorsed, product-focused and seeks to prevent crime, rather than being compliance-based.

The below table highlights the different attributes of each scheme:

Ultimately, SCD indicates that a specific app (or IoT product) has been designed with security and crime prevention at its core, helping to protect its user’s data.

What type of apps are eligible for SCD accreditation?

SCD mobile app accreditation is relevant for any consumer or business app that handles personal, sensitive or high-value data. This includes social, dating, communication, and safety apps where privacy and data integrity are critical.

Can startups and SMEs apply for accreditation?

Absolutely! Smaller-scale apps are just as susceptible to cybercrime – in fact, attackers often prefer them because there are usually fewer security controls, limited monitoring, and slower patching cycles. Therefore, SCD accreditation is just as important for mobile apps of this size.

You can learn more about common app security misconceptions here.

How can consumers identify an SCD accredited app?

Look out for the Secured by Design SCD on the app’s website, in the app store description, or within the app itself. You can also browse accredited mobile apps here.

Does it require a lot of effort, time and resources for an organisation?

Minimal effort and resources are required – your only job is to get certified with the recommended independent third-party testing house. We’ll handle the rest.

Even better, the whole process can take as little as two weeks from your initial enquiry to achieving accreditation, because we understand the urgency of maintaining strong cybersecurity.

What are the benefits of getting SCD accreditation for an app?

SCD accreditation offers a wealth of benefits. Firstly, it delivers reassurance to consumers and boosts trust by demonstrating that your app is credible and security-focused. This is also advantageous from a reputational perspective, helping to position your organisation competitively against others.

“Position your app as a leader in a UK market of over 25,000 apps”

In addition, SCD accreditation helps to futureproof your app by reducing potential liability and ensuring there is robust protect against common cyber threats – keeping your users and their data safe.

Following accreditation, your app will be featured on the Secured by Design website, increasing its visibility. You’ll also gain access to promotional opportunities through the SBD marketing team, such as press releases and social media content.

What if our app fails the accreditation process?

If your app’s certification and documents are rejected, then you will be informed of the decision along with feedback to address the issues identified.

Following this, your app will go through the certification process once more. If the issues have been resolved, then your application will be approved and membership can be completed.

Is SCD accrediation a 'nice to have' or essential?

While not currently mandated, SCD accreditation is rapidly shifting from a ‘nice to have’ feature to a strategic necessity, which is the result of several factors:

Prevalence of cybersecurity

Mobile apps and IoT devices have become prime targets for cybercriminals – failing to implement strong security measures can expose users to significant risks and cause severe reputational damage

Compliance pressure rising

SCD accreditation demonstrates that your app is aligned with recognised UK security standards, which can be particularly beneficial in certain regulated sectors.

Evolving expectations

By validating product-level security, SCD accreditation provides organisations with a unique selling point and a competitive edge in highly saturated markets.

Importance of customer trust

Having police-endorsed accreditation for your app provides a clear, recognisable signal that it has been independently assessed – this can highly influence purchasing decisions for security-conscious buyers.

Minimising the risks

The cost of accreditation should be weighed against the ramifications of a cyberbreach, including:

  • Financial penalties
  • Incident response costs
  • Reputational damage
  • Loss of customer confidence
  • Contract termination

    As the cyber landscape evolves and becomes increasingly precarious, SCD accreditation provides an important mark of credibility for security-conscious organisations. If you are a company looking for SBD membership, it will be a requirement for any IoT connected product or service to meet the requirements of the ‘Secure Connected Device’ accreditation scheme.

    Does accreditation guarantee an app is “hack-proof”?

    No security standard can guarantee 100% protection, but SCD accreditation means the app has met a rigorous, police-approved security benchmark. It’s an assurance that the company has prioritised security and defended against all known, common cyber threats based on global standards.

    Ultimately, it significantly reduces the risk compared to non-accredited apps.


    To find out more or speak to an SBD Development Officer get in touch here.